prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 22 úno 2018 16:57

odehrál sem asi 4 hry a vypadá to dobře, ale dneska sem se podíval na disk že bych ještě neco smazal, ale svítí mi tam že mam pouze 2gb volného místa ze 120gb, jak je to možné když sem mel 17gb? když mrknu do složky a oznacim vsechny soubory a dam vlastnosti, tak mi to da pouze 40gb, kde jen ten zbytek?

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 22 úno 2018 17:44

Nestahovaly se Ti aktualizace systému? Mohlo se Ti taky začít zapisovat body obnovy , které předtím z důvodu nedostatku volného místa nešly.

Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt

Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 22 úno 2018 18:48

aktualizace mam vyple primarne, takze ty urcite ne a nakej bod obnovy jsem delal, ale ze by mel tolik?...

OTL logfile created on: 22.2.2018 18:22:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jenda\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18762)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

15,94 Gb Total Physical Memory | 13,65 Gb Available Physical Memory | 85,67% Memory free
31,87 Gb Paging File | 29,46 Gb Available in Paging File | 92,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 1,87 Gb Free Space | 1,57% Space Free | Partition Type: NTFS
Drive F: | 931,39 Gb Total Space | 559,47 Gb Free Space | 60,07% Space Free | Partition Type: NTFS

Computer Name: JENDA-PC | User Name: Jenda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jenda\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
PRC - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - c:\postgreSQL\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\video.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\libavcodec-57.dll ()
MOD - C:\Program Files (x86)\Steam\libavutil-55.dll ()
MOD - C:\Program Files (x86)\Steam\libswscale-4.dll ()
MOD - C:\Program Files (x86)\Steam\libavformat-57.dll ()
MOD - C:\Program Files (x86)\Steam\libavresample-3.dll ()
MOD - C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\v8.dll ()
MOD - C:\Program Files (x86)\Steam\icui18n.dll ()
MOD - C:\Program Files (x86)\Steam\icuuc.dll ()
MOD - C:\Program Files (x86)\Steam\openvr_api.dll ()
MOD - C:\Program Files (x86)\Steam\winh264.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NVDisplay.ContainerLocalSystem) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe (Futuremark)
SRV - (ZAMSvc) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
SRV - (EasyAntiCheat) -- C:\Windows\SysWOW64\EasyAntiCheat.exe (EasyAntiCheat Ltd)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (HuaweiHiSuiteService64.exe) -- C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe ()
SRV - (TeamViewer) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (postgresql-8.4) -- c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ZAM_Guard) -- C:\Windows\SysNative\drivers\zamguard64.sys (Zemana Ltd.)
DRV:64bit: - (ZAM) -- C:\Windows\SysNative\drivers\zam64.sys (Zemana Ltd.)
DRV:64bit: - (sshid) -- C:\Windows\SysNative\drivers\sshid.sys (SteelSeries ApS)
DRV:64bit: - (hidkmdf) -- C:\Windows\SysNative\drivers\hidkmdf.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (ssdevfactory) -- C:\Windows\SysNative\drivers\ssdevfactory.sys (SteelSeries ApS)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 7B C5 D3 90 E4 78 D3 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.countryCode: "CZ"
FF - prefs.js..browser.search.defaultthis.engineName: "Seznam"
FF - prefs.js..browser.search.region: "CZ"
FF - prefs.js..browser.search.widget.inNavBar: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.151.2: C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.151.2: C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 58.0.2\extensions\\Components: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 58.0.2\extensions\\Plugins: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS

[2015.05.09 23:44:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Extensions
[2017.11.17 15:56:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\SystemExtensionsDev
[2017.11.03 00:04:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data
[2018.02.22 18:14:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2017.11.03 01:06:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2017.11.03 00:39:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\screenshots@mozilla.org
[2018.02.22 12:54:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\sko-extension@firma.seznam.cz
[2017.12.12 23:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions
[2017.11.29 00:39:39 | 002,351,937 | ---- | M] () (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\sko-extension@firma.seznam.cz.xpi
[2017.12.12 23:32:05 | 001,044,671 | ---- | M] () (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2017.01.06 00:33:40 | 000,002,413 | ---- | M] () -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\searchplugins\seznam-avast.xml
[2018.02.08 21:08:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
File not found (No name found) -- C:\USERS\JENDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W4SZHOPX.DEFAULT\EXTENSIONS\SKO-EXTENSION@FIRMA.SEZNAM.CZ

========== Chrome ==========

CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\
CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\

O1 HOSTS File: ([2018.02.19 17:23:07 | 000,000,841 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Skype for Desktop] C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Internet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{12E81E8B-FB4F-4FFA-8443-A86BFF443193}: DhcpNameServer = 10.0.1.138
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2018.02.20 22:37:14 | 000,000,000 | ---D | M] - F:\Auto -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2018.02.22 18:12:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Jenda\Desktop\OTL.exe
[2018.02.22 18:05:30 | 000,000,000 | ---D | C] -- C:\Users\Jenda\Desktop\15s
[2018.02.19 20:00:12 | 000,000,000 | ---D | C] -- C:\FRST
[2018.02.19 19:58:43 | 002,403,840 | ---- | C] (Farbar) -- C:\Users\Jenda\Desktop\FRST64.exe
[2018.02.19 19:53:06 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2018.02.17 22:24:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2018.02.17 22:24:47 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2018.02.17 22:24:17 | 000,201,728 | ---- | C] (OldTimer Tools) -- C:\Users\Jenda\Desktop\OTC(1).exe
[2018.02.17 22:23:44 | 011,217,568 | ---- | C] (Piriform Ltd) -- C:\Users\Jenda\Desktop\ccsetup540(1).exe
[2018.02.17 22:23:40 | 011,217,568 | ---- | C] (Piriform Ltd) -- C:\Users\Jenda\Desktop\ccsetup540.exe
[2018.02.17 22:22:41 | 000,000,000 | ---D | C] -- C:\Users\Jenda\Desktop\backups
[2018.02.17 17:28:03 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2018.02.17 17:13:04 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
[2018.02.17 17:13:04 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
[2018.02.17 17:13:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
[2018.02.17 17:13:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zemana AntiMalware
[2018.02.17 17:12:53 | 000,000,000 | ---D | C] -- C:\Users\Jenda\AppData\Local\Zemana
[2018.02.17 16:46:13 | 006,625,600 | ---- | C] (Zemana Ltd. ) -- C:\Users\Jenda\Desktop\Zemana.AntiMalware.Setup.exe
[2018.02.17 08:16:00 | 000,000,000 | ---D | C] -- C:\Users\Jenda\AppData\Local\Apple
[2018.02.16 19:32:35 | 000,000,000 | ---D | C] -- C:\zoek_backup
[2018.02.16 16:44:42 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2018.02.16 13:01:31 | 026,937,928 | ---- | C] (Adlice Software) -- C:\Users\Jenda\Desktop\RogueKiller_portable64.exe
[2018.02.16 13:00:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2018.02.16 13:00:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2018.02.16 13:00:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
[2018.02.16 12:58:38 | 191,548,536 | ---- | C] (Sophos Limited) -- C:\Users\Jenda\Desktop\Sophos Virus Removal Tool.exe
[2018.02.16 12:50:17 | 001,790,024 | ---- | C] (Malwarebytes) -- C:\Users\Jenda\Desktop\JRT.exe
[2018.02.16 02:58:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2018.02.16 02:58:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CrystalDiskInfo
[2018.02.16 02:54:19 | 003,947,992 | ---- | C] (Crystal Dew World ) -- C:\Users\Jenda\Desktop\CrystalDiskInfo7_5_1.exe
[2018.02.16 02:52:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2018.02.16 02:52:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2018.02.16 02:47:18 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2018.02.16 02:46:16 | 000,000,000 | ---D | C] -- C:\Users\Jenda\AppData\Local\Apps
[2018.02.16 01:35:18 | 008,222,496 | ---- | C] (Malwarebytes) -- C:\Users\Jenda\Desktop\AdwCleaner.exe
[2018.02.16 01:34:36 | 067,502,232 | ---- | C] (Malwarebytes ) -- C:\Users\Jenda\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3958.exe
[2018.02.16 01:33:50 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Jenda\Desktop\TFC.exe
[2018.02.15 23:56:32 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\Jenda\Desktop\ATF-Cleaner.exe
[2018.02.15 21:51:39 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Jenda\Desktop\HijackThis.exe

========== Files - Modified Within 30 Days ==========

[2018.02.22 18:23:31 | 000,188,302 | ---- | M] () -- C:\Windows\ZAM_Guard.krnl.trace
[2018.02.22 18:23:30 | 000,204,702 | ---- | M] () -- C:\Windows\ZAM.krnl.trace
[2018.02.22 18:12:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jenda\Desktop\OTL.exe
[2018.02.22 14:10:07 | 000,001,167 | ---- | M] () -- C:\Users\Jenda\Desktop\PokerSnowie.lnk
[2018.02.22 13:02:32 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2018.02.22 13:02:32 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2018.02.22 13:00:35 | 001,584,554 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2018.02.22 13:00:35 | 000,668,866 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2018.02.22 13:00:35 | 000,654,254 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2018.02.22 13:00:35 | 000,141,526 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2018.02.22 13:00:35 | 000,122,126 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2018.02.22 12:54:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2018.02.22 12:54:38 | 4242,784,254 | -HS- | M] () -- C:\hiberfil.sys
[2018.02.21 23:23:25 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018.02.21 23:23:25 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2018.02.19 19:58:45 | 002,403,840 | ---- | M] (Farbar) -- C:\Users\Jenda\Desktop\FRST64.exe
[2018.02.19 17:23:07 | 000,000,841 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2018.02.17 22:30:02 | 000,029,878 | ---- | M] () -- C:\Users\Jenda\Desktop\cc_20180217_222944.reg
[2018.02.17 22:24:20 | 000,201,728 | ---- | M] (OldTimer Tools) -- C:\Users\Jenda\Desktop\OTC(1).exe
[2018.02.17 22:23:51 | 011,217,568 | ---- | M] (Piriform Ltd) -- C:\Users\Jenda\Desktop\ccsetup540(1).exe
[2018.02.17 22:23:42 | 011,217,568 | ---- | M] (Piriform Ltd) -- C:\Users\Jenda\Desktop\ccsetup540.exe
[2018.02.17 21:02:33 | 000,000,512 | ---- | M] () -- C:\Users\Jenda\Desktop\MBR.dat
[2018.02.17 18:29:54 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\HoldemManager2.lnk
[2018.02.17 17:13:04 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
[2018.02.17 17:13:04 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
[2018.02.17 17:13:04 | 000,001,148 | ---- | M] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2018.02.17 16:46:14 | 006,625,600 | ---- | M] (Zemana Ltd. ) -- C:\Users\Jenda\Desktop\Zemana.AntiMalware.Setup.exe
[2018.02.17 16:45:06 | 000,028,272 | ---- | M] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2018.02.16 19:32:23 | 001,168,896 | ---- | M] () -- C:\Users\Jenda\Desktop\zoek.exe
[2018.02.16 13:01:36 | 026,937,928 | ---- | M] (Adlice Software) -- C:\Users\Jenda\Desktop\RogueKiller_portable64.exe
[2018.02.16 13:00:30 | 000,002,759 | ---- | M] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2018.02.16 13:00:01 | 191,548,536 | ---- | M] (Sophos Limited) -- C:\Users\Jenda\Desktop\Sophos Virus Removal Tool.exe
[2018.02.16 12:50:23 | 001,790,024 | ---- | M] (Malwarebytes) -- C:\Users\Jenda\Desktop\JRT.exe
[2018.02.16 02:58:30 | 000,001,200 | ---- | M] () -- C:\Users\Jenda\Desktop\CrystalDiskInfo.lnk
[2018.02.16 02:54:25 | 003,947,992 | ---- | M] (Crystal Dew World ) -- C:\Users\Jenda\Desktop\CrystalDiskInfo7_5_1.exe
[2018.02.16 01:35:19 | 008,222,496 | ---- | M] (Malwarebytes) -- C:\Users\Jenda\Desktop\AdwCleaner.exe
[2018.02.16 01:34:55 | 067,502,232 | ---- | M] (Malwarebytes ) -- C:\Users\Jenda\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3958.exe
[2018.02.16 01:33:52 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Jenda\Desktop\TFC.exe
[2018.02.15 23:56:35 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\Jenda\Desktop\ATF-Cleaner.exe
[2018.02.15 21:51:41 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Jenda\Desktop\HijackThis.exe
[2018.02.14 03:47:38 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2018.02.07 22:24:10 | 000,001,306 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2018.02.06 21:22:04 | 000,803,328 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2018.02.06 21:22:04 | 000,144,896 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2018.02.21 12:31:08 | 000,204,468 | ---- | C] () -- C:\Windows\ZAM.krnl.trace
[2018.02.21 12:31:08 | 000,188,056 | ---- | C] () -- C:\Windows\ZAM_Guard.krnl.trace
[2018.02.17 22:29:50 | 000,029,878 | ---- | C] () -- C:\Users\Jenda\Desktop\cc_20180217_222944.reg
[2018.02.17 22:24:48 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2018.02.17 21:02:02 | 000,000,512 | ---- | C] () -- C:\Users\Jenda\Desktop\MBR.dat
[2018.02.17 17:13:04 | 000,001,148 | ---- | C] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2018.02.16 19:32:19 | 001,168,896 | ---- | C] () -- C:\Users\Jenda\Desktop\zoek.exe
[2018.02.16 16:45:07 | 000,028,272 | ---- | C] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2018.02.16 13:00:30 | 000,002,759 | ---- | C] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2018.02.16 02:58:30 | 000,001,200 | ---- | C] () -- C:\Users\Jenda\Desktop\CrystalDiskInfo.lnk
[2018.02.16 02:52:22 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018.02.16 02:52:20 | 000,077,432 | ---- | C] () -- C:\Windows\SysNative\drivers\mbae64.sys
[2018.01.25 22:24:42 | 4242,784,254 | -HS- | C] () -- C:\hiberfil.sys
[2017.11.07 00:52:51 | 000,525,088 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1.dll
[2017.11.07 00:52:51 | 000,233,760 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo.exe
[2017.08.26 11:15:42 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2017.08.26 11:09:05 | 000,518,144 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2017.06.15 20:32:56 | 000,525,088 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1-1-0-51-0.dll
[2017.06.15 20:32:50 | 000,233,760 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo-1-1-0-51-0.exe
[2015.07.14 16:30:37 | 000,003,060 | ---- | C] () -- C:\Users\Jenda\URPreferences.xml

========== ZeroAccess Check ==========

[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2017.05.10 16:29:53 | 014,183,936 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2017.05.10 16:12:47 | 012,880,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2016.08.03 16:01:43 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Battle.net
[2015.09.17 00:10:13 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\BSplayer
[2015.07.07 21:34:22 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\BSplayer Pro
[2015.10.05 17:25:05 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\CardCasino Poker
[2016.10.01 12:46:21 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\cef3-cache
[2017.08.02 19:58:50 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\EasyAntiCheat
[2017.12.01 01:06:48 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Electrum
[2015.05.10 00:31:41 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\HEM Data
[2018.02.22 18:19:57 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\HoldemManager
[2016.11.15 02:13:46 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Jivaro ehf
[2017.10.03 17:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\OBS
[2015.11.27 01:37:22 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Oracle
[2017.01.15 20:17:34 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\PacificPoker
[2016.10.01 12:46:16 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Party
[2015.05.10 00:31:43 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Roaming
[2018.02.17 18:33:20 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\Seznam.cz
[2015.05.10 00:42:29 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\SitNGoWizard
[2018.01.19 05:00:13 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\steelseries-engine-3-client
[2015.05.10 17:10:44 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\T-Mobile
[2015.05.10 00:54:20 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\TableOptimizer
[2017.11.02 23:56:53 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\TeamViewer
[2018.02.21 23:12:27 | 000,000,000 | ---D | M] -- C:\Users\Jenda\AppData\Roaming\TS3Client

========== Purity Check ==========



< End of report >

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 22 úno 2018 18:49

OTL Extras logfile created on: 22.2.2018 18:22:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jenda\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18762)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

15,94 Gb Total Physical Memory | 13,65 Gb Available Physical Memory | 85,67% Memory free
31,87 Gb Paging File | 29,46 Gb Available in Paging File | 92,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 1,87 Gb Free Space | 1,57% Space Free | Partition Type: NTFS
Drive F: | 931,39 Gb Total Space | 559,47 Gb Free Space | 60,07% Space Free | Partition Type: NTFS

Computer Name: JENDA-PC | User Name: Jenda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0BAFCE01-C07F-4B5C-965C-071651C59D1C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0C1662FF-EF3D-44E8-ABBE-742B402FE714}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{25B592A0-9634-42D2-9A07-21F9B14363F6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{277367A7-1691-47CC-AD8C-70129BDABB37}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2FEA179C-E9DE-4527-A7F9-E9D219983163}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{30A4F00D-07B9-4F8D-9B5C-D6EA0C0153EA}" = rport=139 | protocol=6 | dir=out | app=system |
"{40CCE789-D743-4F7B-9F96-D06EA8DF5702}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{45FA0CE3-0C8F-4264-BC8F-75D00B93D63E}" = lport=139 | protocol=6 | dir=in | app=system |
"{55205C45-AC26-403A-B760-3CF356EAF5E8}" = rport=137 | protocol=17 | dir=out | app=system |
"{5581E1E9-5E8F-404F-8EDE-5DC5A3070805}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{614993CB-F80E-4A57-8E83-AF3B30369B53}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{620380FA-F7EE-4266-B546-FEA5E7F3C4E6}" = lport=138 | protocol=17 | dir=in | app=system |
"{71A0E72F-0268-4EC7-8765-7123C31EF998}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{73293143-1E6B-43EB-8135-75A0B0F35F54}" = lport=10243 | protocol=6 | dir=in | app=system |
"{80D45C31-CC85-4289-9996-249C612371A3}" = rport=138 | protocol=17 | dir=out | app=system |
"{83A2B9BC-D771-439C-9DD4-3E5DAA448857}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{85CB3E68-7289-45D3-849C-F06BF88A5CAF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9DBBFDFE-99F9-4696-A95F-F8D4133C2DB3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A64038B3-3CE6-4F74-ADA5-53E752E22D20}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A72CC1F2-20B9-425B-9047-65D6B9E380DE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7C5FDC4-5239-4175-A1BD-E1AAD3550D18}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{B71113A1-E50D-4DC5-9E05-72626E98A2BC}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{B8EDD15C-5581-4F90-A226-4AC0DD1064F5}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C5F4DB78-2779-4B03-A873-25386F0D81EC}" = lport=445 | protocol=6 | dir=in | app=system |
"{C7DE60EF-D2FE-4F3C-A7AD-8A1A82D54CB3}" = rport=445 | protocol=6 | dir=out | app=system |
"{D8894E68-1E48-4642-9C14-75E6515DB427}" = lport=5432 | protocol=6 | dir=in | name=postgres |
"{DD833AE2-E27A-44BC-9415-75CE4C3867C0}" = lport=137 | protocol=17 | dir=in | app=system |
"{E062ED78-A6F0-4B9A-AAD3-B1DC6C3CE05F}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{E6C92589-4E34-454D-92B7-36C5E1FD84DE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EA4C7858-9B20-47A2-8FD7-EB13405BAB2C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{EAF6E34A-0592-4A11-86E5-9D162E03545E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F1E37423-9B8C-4CDE-B4CC-45F8E7769700}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FF5C8555-73EE-4088-B5AE-550142FD53B7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{038D3C03-E6C8-43DC-BBC7-AB019DEB5E69}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{0CCEBB77-C55A-4AE0-9A0B-EA00DA033200}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{14EF55CF-C556-4396-B794-94507AD5C53C}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{2B24BB5C-4504-4FF7-87E1-756E5BEDE15A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{30D70D1C-58C0-4CD5-BC3F-B8DF74892788}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3333751F-DF3B-40EC-B404-4A9C2ECD96F4}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{3CD9EDDC-B2C8-462B-85A9-EDC5D20A28D9}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{3FDDD62C-BEC6-4BA2-AB79-2443EDCBB693}" = protocol=17 | dir=in | app=f:\dota\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe |
"{43E72258-DE8F-4C56-9A68-83D7D2F038B7}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{4424AF3F-4DD4-4DAD-B8C9-64DEB15719D5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4DF42937-48C1-4591-BD88-07C9DC1747E5}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{4E9CE439-C92E-40FC-BAC2-891E75EE6CAA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4F0713F5-B0D2-4927-8330-D7048E115CF0}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{53260DC4-EE49-457E-B209-AFDE5DD1B80E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{54688C11-5E0A-4917-BE6B-BABAE4ABBFCA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{59E3EF64-2878-4928-8D25-6581A6964648}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe |
"{6489A43B-2B15-4D1D-A8FF-355280990757}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{65143DC9-4704-40A4-A7C1-E7E73D7085B3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe |
"{653C2BEF-6E96-4D1B-B5CE-4B2295D55A81}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{686BC59C-D366-4D93-92CC-726E033E99C7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{693FB9EB-3A25-4C7D-B59D-FBE1607E1E8D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe |
"{726F1491-94F1-4531-B138-AAA452F7EBCC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe |
"{73B10F63-BF9A-48E9-BFBE-072208CAAAA9}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{7408943D-05B0-4F46-8AF9-EB32715756CB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{80A4D746-F5F1-4250-8B82-330108DCDB09}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{811C1D21-1EAB-4D99-ACE2-325F7C91E71A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
"{8867FD33-6506-4709-8262-8CD5E5B282AF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8AFE7D0F-312E-46D6-A41A-DA4AD7390B06}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{925A7BD6-30AC-48F8-9269-C1AFCA74A907}" = protocol=6 | dir=in | app=f:\dota\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe |
"{A593BE8D-4595-45CD-BF1A-9D4AF65CC574}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A9042524-B741-40B4-934B-D18484684DF4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{ACB569ED-625D-49C1-AC40-B6F227350A12}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{ACC137E7-F440-425A-9BA4-183C077C940A}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{AD9EE4FE-952D-4882-928D-A3AEE0D056EF}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AEB56F54-8CED-4CB3-BCDB-D8E2CE488B01}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{C22B652D-F170-4F25-8BDB-085DD0F71972}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C55E301D-0250-4B72-87E0-9140FEC16200}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C8085976-A888-4C6B-A51E-F465A11E7417}" = protocol=6 | dir=out | app=system |
"{C9DA8370-038B-4D1A-B279-9935FBE359BA}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{C9E0287C-2006-4050-9EDD-5827116C67BF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CBAA0380-4D16-4C86-9686-78AED3FDD005}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
"{CFD1FAF6-1059-40A0-94B4-84E5C271A974}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D28D0CE6-1A6A-4ED9-937D-7D49EA88372C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{D3034C91-1503-4F32-93BA-5CE8DED86BAF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DB8F2E46-615D-40BA-9136-5EBA332A18BA}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{DE6D80F1-A30C-4BD9-BFE9-08A1342FCAE5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{DE78BBD8-34F5-4BC1-A58C-33F72659EDF2}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{EA0FBB35-4550-4B6C-9402-317558D38331}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FDB1E5CF-5428-444D-BA3C-7F59026875CC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{EFC3661D-1B9D-45AE-A474-5FDEC634ADC6}C:\program files\bitcoin\bitcoin-qt.exe" = protocol=6 | dir=in | app=c:\program files\bitcoin\bitcoin-qt.exe |
"UDP Query User{B2CC1B19-9BAB-4A2E-B724-DBC7432A8676}C:\program files\bitcoin\bitcoin-qt.exe" = protocol=17 | dir=in | app=c:\program files\bitcoin\bitcoin-qt.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D3E9E15-DE7A-300B-96F1-B4AF12B96488}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23026
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F64180151F0}" = Java 8 Update 151 (64-bit)
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes verze 3.3.1.2183
"{38AFD787-4D2E-4442-92D2-7739F5F92CF4}_is1" = SoftPerfect WiFi Guard version 1.0.3
"{3C38CA01-7933-31E7-A1F6-EAA1DF9BEDF3}" = Microsoft .NET Framework 4.6.1 (CSY)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}" = Bonjour
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029" = Microsoft .NET Framework 4.6.1 (čeština)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.7
"{977D1ABF-4089-4CA7-BA33-CC75808B7ACE}" = Intel® Trusted Connect Service Client
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 385.41
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 385.41
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 385.41
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.3.34.27
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer" = NVIDIA Display Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS" = NVIDIA Display Container LS
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog" = NVIDIA Display Watchdog Plugin
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer" = NVIDIA Display Session Container
"{BC958BD2-5DAC-3862-BB1A-C1BE0790438D}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23026
"{BCF0C1F7-671C-3922-A7EA-8AC11F4FC0EB}" = Microsoft .NET Framework 4.7
"{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}" = Podpora aplikací Apple (64bitová)
"{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}" = Apple Mobile Device Support
"{EB7E0903-21E9-4851-99D3-D7E54B51031C}" = iTunes
"0AEBEF6F936CFE16E003F7E141631FAB754D9816" = Windows Driver Package - Microsoft (xusb21) XnaComposite (08/13/2009 2.1.0.1349)
"CCleaner" = CCleaner
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.32
"HWiNFO64_is1" = HWiNFO64 Version 4.62
"Mozilla Firefox 58.0.2 (x64 cs)" = Mozilla Firefox 58.0.2 (x64 cs)
"Steam App 570" = Dota 2
"Steam App 730" = Counter-Strike: Global Offensive
"SteelSeries Engine 3" = SteelSeries Engine 3.11.11
"VulkanRT1.0.51.0" = Vulkan Run Time Libraries 1.0.51.0
"WinRAR archiver" = WinRAR 5.21 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1E80B1FD-8A06-4B70-86B6-CEB9E5C8EFB1}" = SessionLord
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{3D1290E6-1F77-46D5-A715-A56679C8D4E3}" = Podpora aplikací Apple (32bitová)
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ceecc68-b7e1-4161-8a66-e14102ae4a39}" = SessionLord
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{69BCE4AC-9572-3271-A2FB-9423BDA36A43}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{80DAA2DD-18D3-4C18-927E-8D150C112912}" = Futuremark SystemInfo
"{86D09F48-CDAB-4B4C-8806-F6C16F17935A}" = PokerStrategy.com Equilab
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1" = Zemana AntiMalware
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-0804-1033-1959-001824261196}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1029-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Czech
"{B829E117-D072-41EA-9606-9826A38D34C1}" = Sophos Virus Removal Tool
"{BBF2AC74-720C-3CB3-8291-5E34039232FA}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215
"{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}" = Apple Software Update
"{e2803110-78b3-4664-a479-3611a381656a}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
"{e46eca4f-393b-40df-9f49-076faf788d83}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
"{ED175C0B-CA34-44DD-B37F-D2705FAF8673}" = 888poker
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"Adobe Flash Player ActiveX" = Adobe Flash Player 28 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 28 NPAPI
"Battle.net" = Battle.net
"BSPlayerf" = BS.Player FREE
"CrystalDiskInfo_is1" = CrystalDiskInfo 7.5.1
"Google Chrome" = Google Chrome
"Hi Suite" = HiSuite
"HoldemManager2" = Holdem Manager 2
"HoldemResources Calculator" = HoldemResources Calculator
"HWiNFO32_is1" = HWiNFO32 Version 4.36
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OCCT" = OCCT 4.5.1
"Open Broadcaster Software" = Open Broadcaster Software
"PartyPoker" = partypoker
"PokerSnowie_is1" = PokerSnowie
"PokerStars.cz" = PokerStars.cz
"PokerStars.eu" = PokerStars.eu
"PostgreSQL 8.4" = PostgreSQL 8.4
"Skype_is1" = Skype verze 8.15
"Steam" = Steam
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TeamViewer" = TeamViewer 11

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"bcfaecc00feb2640" = Icmizer
"InstallShield_{ED175C0B-CA34-44DD-B37F-D2705FAF8673}" = 888poker
"SeznamInstall" = Seznam Software

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 21.2.2018 22:22:09 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:22:39 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:23:14 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:24:09 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:24:14 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:24:24 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 21.2.2018 22:25:25 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description =

Error - 22.2.2018 7:54:44 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description = 2018-02-22 12:54:44 CETFATAL: the database system is starting up

Error - 22.2.2018 7:56:32 | Computer Name = Jenda-PC | Source = WinMgmt | ID = 10
Description =

Error - 22.2.2018 13:11:01 | Computer Name = Jenda-PC | Source = PostgreSQL | ID = 0
Description = 2018-02-22 18:11:01 CETERROR: database "15s" is being accessed by
other users 2018-02-22 18:11:01 CETDETAIL: There are 1 other session(s) using the
database. 2018-02-22 18:11:01 CETSTATEMENT: DROP DATABASE "15s"

[ Media Center Events ]
Error - 9.10.2016 14:24:44 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 20:24:44 - Načtení položky Directory se nezdařilo. (Chyba: Vzdálený
název nelze rozpoznat: 'data.tvdownload.microsoft.com')

Error - 12.10.2016 11:29:18 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 17:29:18 - Chyba při připojování k Internetu 17:29:18 - Nelze kontaktovat
server..

Error - 12.10.2016 12:30:05 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 18:30:05 - Chyba při připojování k Internetu 18:30:05 - Nelze kontaktovat
server..

Error - 29.3.2017 14:42:43 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 20:42:43 - Chyba při připojování k Internetu 20:42:43 - Nelze kontaktovat
server..

Error - 29.8.2017 11:52:04 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 17:52:04 - Chyba při připojování k Internetu 17:52:04 - Nelze kontaktovat
server..

Error - 31.10.2017 11:35:26 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 16:35:26 - Chyba při připojování k Internetu 16:35:26 - Nelze kontaktovat
server..

Error - 30.12.2017 12:00:08 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 17:00:08 - Chyba při připojování k Internetu 17:00:08 - Nelze kontaktovat
server..

Error - 30.12.2017 13:00:13 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 18:00:13 - Chyba při připojování k Internetu 18:00:13 - Nelze kontaktovat
server..

Error - 30.12.2017 14:00:18 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 19:00:18 - Chyba při připojování k Internetu 19:00:18 - Nelze kontaktovat
server..

Error - 30.12.2017 15:00:23 | Computer Name = Jenda-PC | Source = MCUpdate | ID = 0
Description = 20:00:23 - Chyba při připojování k Internetu 20:00:23 - Nelze kontaktovat
server..

[ System Events ]
Error - 19.2.2018 18:25:47 | Computer Name = Jenda-PC | Source = Service Control Manager | ID = 7034
Description = Služba Intel(R) Management and Security Application User Notification
Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error - 19.2.2018 18:27:03 | Computer Name = Jenda-PC | Source = volmgr | ID = 262189
Description = Systému se nepodařilo úspěšně načíst ovladač výpisu stavu systému.

Error - 19.2.2018 18:27:03 | Computer Name = Jenda-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 19.2.2018 18:27:05 | Computer Name = Jenda-PC | Source = volmgr | ID = 262189
Description = Systému se nepodařilo úspěšně načíst ovladač výpisu stavu systému.

Error - 20.2.2018 5:55:48 | Computer Name = Jenda-PC | Source = volsnap | ID = 393251
Description = Stínové kopie svazku C: byly přerušeny, protože se nepodařilo zvětšit
úložiště stínové kopie.

Error - 20.2.2018 9:04:42 | Computer Name = Jenda-PC | Source = volmgr | ID = 262189
Description = Systému se nepodařilo úspěšně načíst ovladač výpisu stavu systému.

Error - 20.2.2018 9:04:42 | Computer Name = Jenda-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 20.2.2018 9:04:44 | Computer Name = Jenda-PC | Source = volmgr | ID = 262189
Description = Systému se nepodařilo úspěšně načíst ovladač výpisu stavu systému.

Error - 21.2.2018 7:31:03 | Computer Name = Jenda-PC | Source = volmgr | ID = 262189
Description = Systému se nepodařilo úspěšně načíst ovladač výpisu stavu systému.

Error - 21.2.2018 7:31:03 | Computer Name = Jenda-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.


< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 22 úno 2018 19:48

Zemana , Sophos , Seznam odinstaluj.

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll File not found
[2015.05.09 23:44:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Extensions
[2017.11.17 15:56:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\SystemExtensionsDev
[2017.11.03 00:04:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data
[2018.02.22 18:14:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2017.11.03 01:06:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2017.11.03 00:39:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\screenshots@mozilla.org
[2018.02.22 12:54:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\sko-extension@firma.seznam.cz
[2017.12.12 23:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions
[2017.11.29 00:39:39 | 002,351,937 | ---- | M] () (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\sko-extension@firma.seznam.cz.xpi
[2017.12.12 23:32:05 | 001,044,671 | ---- | M] () (No name found) -- C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2018.02.08 21:08:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
File not found (No name found) -- C:\USERS\JENDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W4SZHOPX.DEFAULT\EXTENSIONS\SKO-EXTENSION@FIRMA.SEZNAM.CZ
CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\
CHR - Extension: No name found = C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2017.05.10 16:29:53 | 014,183,936 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2017.05.10 16:12:47 | 012,880,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\ProgramData\DP45977C.lfl

:Reg
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[EMPTYJAVA]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Drive C: | 119,14 Gb Total Space | 1,87 Gb Free Space | 1,57% Space Free | Partition Type: NTFS

zkontroluj si po restartu , po OTL , kolik máš na disku volného místa.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 22 úno 2018 20:10

po OTL mam 5,56gb mista

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Extensions folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\SystemExtensionsDev folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{ea614400-e918-4741-9a97-7a972ff7c30b} folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\sko-extension@firma.seznam.cz folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\screenshots@mozilla.org folder moved successfully.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data folder moved successfully.
Folder C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\ not found.
Folder C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\{ea614400-e918-4741-9a97-7a972ff7c30b}\ not found.
Folder C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\screenshots@mozilla.org\ not found.
Folder C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\browser-extension-data\sko-extension@firma.seznam.cz\ not found.
C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions folder moved successfully.
File C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\sko-extension@firma.seznam.cz.xpi not found.
File C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\w4szhopx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_metadata folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\zh_TW folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\zh_CN folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\vi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\uk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\tr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\th folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\sv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\sr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\sl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\sk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ru folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ro folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\pt_PT folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\pt_BR folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\pl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\no folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\nl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ms folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\lv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\lt folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ko folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ja folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\it folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\id folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\hu folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\hi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\he folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\fr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\fil folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\fi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\et folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\es_419 folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\es folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\en_US folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\en_GB folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\el folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\de folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\da folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\cs folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ca folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\bg folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales\ar folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\_locales folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1 folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_metadata folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\zh_TW folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\zh_CN folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\vi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\uk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\tr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\th folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\sv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\sr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\sl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\sk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\ru folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\ro folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\pt_PT folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\pt_BR folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\pl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\nl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\nb folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\lv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\lt folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\ko folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\ja folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\it folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\id folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\hu folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\hr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\hi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\fr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\fil folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\fi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\et folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\es_419 folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\es folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\en_GB folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\en folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\el folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\de folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\da folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\cs folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\ca folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales\bg folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\_locales folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\images folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\html folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1\css folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_1 folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_metadata folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\zh_TW folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\zh folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\vi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\uk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\tr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\th folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\te folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ta folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\sw folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\sv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\sr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\sl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\sk folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ru folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ro folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\pt folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\pl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\nl folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\nb folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ms folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\mr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ml folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\lv folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\lt folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ko folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\kn folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ja folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\iw folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\it folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\id folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\hu folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\hr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\hi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\gu folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\fr folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\fil folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\fi folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\fa folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\et folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\es folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\en folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\el folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\de folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\da folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\cs folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ca folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\bn folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\bg folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\ar folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales\am folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\_locales folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\cloud_route_details folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1\cast_setup folder moved successfully.
C:\Users\Jenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6417.1211.0.0_1 folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\http\0x00000001\ deleted successfully.
File Protocol\Handler\http\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\http\oledb\ deleted successfully.
File Protocol\Handler\http\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\https\0x00000001\ deleted successfully.
File Protocol\Handler\https\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\https\oledb\ deleted successfully.
File Protocol\Handler\https\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.
File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.
File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.
File Protocol\Handler\mso-offdap - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap11\ deleted successfully.
File Protocol\Handler\mso-offdap11 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\Windows\assembly\Desktop.ini moved successfully.
File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
File\Folder c:\windows\Tasks\*.job not found.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
C:\ProgramData\DP45977C.lfl moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Jenda
->Temp folder emptied: 45450067 bytes
->Temporary Internet Files folder emptied: 9035 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 307960840 bytes
->Google Chrome cache emptied: 108966664 bytes
->Flash cache emptied: 0 bytes

User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Subs
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11024 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 441,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Jenda
->Flash cache emptied: 0 bytes

User: postgres

User: Public

User: Subs

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTL Restore Point
Restore point Set: OTL Restore Point

[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Jenda
->Java cache emptied: 0 bytes

User: postgres

User: Public

User: Subs

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02222018_200525

Files\Folders moved on Reboot...
C:\Users\Jenda\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Jenda\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 22 úno 2018 21:06

Budeš m muset mazat dál , tohle je málo.. :evil:
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 22 úno 2018 21:58

ja uz nemam co mazat ale, mam na tom disku jen winny, par programu a to csgo.... filmy, hudbu, atd. mam vedle na hdd

btw. ted koukam a mam najednou 7gb mista :D to je jak kdyby to tam psalo uplne nahodne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 22 úno 2018 22:32

Vyčisti systém CCleanerem

no je to pořád málo a windows se pak chová nestandartně..chybou je dávat systém na tak malý disk.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 23 úno 2018 01:23

maly disk? windows maji pokud vim tak 20-30gb ne?, v programech mam tak 25gb, takze nekde schazi 60gb

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 23 úno 2018 10:14

jo windows stáhnutý , ale aktualizace disk velmi rychle zaplní. Nabaluje se na ně kdeco. Strašně rychle roste velikost windows. 120Gb disk na win a hry je dnes žalostně málo.
můžeš taky použít funkci vyčištění disku..
https://www.svethardware.cz/forum/showt ... a-na-disku
Nejlepší je udělat bitovou kopii disku a pak jí přesunout na nový , větší disk.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Lagett
nováček
Příspěvky: 26
Registrován: říjen 17
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod Lagett » 23 úno 2018 22:03

premejslim ze udelam komplet reinstalaci systemu a soupnu winny na hdd... mam jeden databazovy program ktery pouzivam k Pokeru a ten bych chtěl mit na ssd, kvuli lepsi rychlosti... mohl by byt pak problem pri prenosu mezi hdd kde budou winndows a ssd kde budou ostatni programy? nebo jak to funguje?


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 15 hostů